This command captures incoming and outgoing packets on different monitoring ports that match the specified criteria. If you have configured the Sensor to receive and send traffic on different ports, you can use this command to capture packets.
The captured packets are saved in the /tftpboot/capture.pcap file on the Sensor. The saved file is sent to the Manager or a SCP server based on the configuration made in the Manager. If you have configured the Manager to send captured packets to a SPAN port, you cannot capture packets by using this command.
Note
You can capture packets from the Manager as well. If the Manager is in the process of capturing packets, and at the same time, you run this command, the Sensor will display a message that a packet capture process is already running. Similarly, if you have started packet capture from the CLI, the Manager displays the packet capture Status as Running. In the Manager, you cannot stop a packet capture session that is started in the CLI and vice-versa. As a best practice, you should start and stop a packet capture session from the same place: either from the CLI or from the Manager.
Syntax:
pktcapture intfport-pair <monitoring_port1>-<monitoring_port2> <filter>
Parameter | Description |
|---|---|
monitoring_port1 | Port for capturing incoming packets |
monitoring_port2 | Port for capturing outgoing packets |
filter | BPF (Berkeley Packet Filter) for capturing packets. If no filter is provided, all packets are captured.
|
Note
For NS series Sensors (except NS3600, NS3500, and NS3x00), the monitoring ports will be in the format "gx/(x or y)". For NS3600, NS3500, and NS3x00 Sensors, the monitoring ports will be in the format "x". For Virtual IPS Sensors, the monitoring ports will be in the format "x".
Sample Output:
intruShell@john> pktcapture intfport-pair g3/1-g3/2 ""
Packet capture file will be sent to SCP server, as per configuration.
Do you want to proceed with packet capture session?
Tip: Press "ctrl+k" to terminate a packet capture session.
Please enter Y to confirm: y
pktcapture: capture all...
08:26:47.784115 IP 1.1.1.9.50573 > 1.1.1.10.80: Flags [S], seq 101908577, win 14600, options [mss 1460,sackOK,TS val 2478593938 ecr 0,nop,wscale 6], length 0
08:26:47.784117 IP 1.1.1.9.50573 > 1.1.1.10.80: Flags [.], ack 4187117816, win 229, options [nop,nop,TS val 2478593939 ecr 2478581502], length 0
Applicable to:
NS9600 (standalone), NS9500 (standalone), NS9x00, NS7600, NS7500, NS7x50, NS7x00, NS5x00, NS3600, NS3500, NS3x00 series, and Virtual IPS Sensors.